Backdoor

Remcos.Backdoor.Bot.DDS removal tips

Malware Removal

The Remcos.Backdoor.Bot.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Remcos.Backdoor.Bot.DDS virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Remcos malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Remcos.Backdoor.Bot.DDS?


File Info:

name: F650D24E0C240B987C79.mlw
path: /opt/CAPEv2/storage/binaries/0093170dc61ea8c104a5b0279bd6bba82636a6f7af3c26384770d3b9425e5625
crc32: 7B694C6C
md5: f650d24e0c240b987c792065c7febc80
sha1: 547a00343404953fde6de33b29b7d3b16b48f44f
sha256: 0093170dc61ea8c104a5b0279bd6bba82636a6f7af3c26384770d3b9425e5625
sha512: ad66ccc05c181ab402bf9de469c1234c905085f4c2f3f50d9de841bf7902f05f22d7f1590aa0aa87c4005cf97c09ffd9782b54f3670442b0f39628e4cbea0a79
ssdeep: 6144:8qYktk/thubEctguZK6iXoKLnk586i/f7rG9VLdAYNAO2nOX2Nd0cNyraS:8qYktkO4cpK4KoK6i/f7rQdAn3N++S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC949E11B981C432C1B621700E29EB759ABCBD212935597B63E95D9BFE700C0F73A763
sha3_384: 70cdfc3ca0a4d3f5d36ad5cbc8ed8aa7d42b0a78a10dd942ba19bd0c6c201e72b86aa21068fa79bead85e681b373ff77
ep_bytes: e88d040000e98efeffff558bec56ff75
timestamp: 2023-05-23 16:53:47

Version Info:

0: [No Data]

Remcos.Backdoor.Bot.DDS also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanDeepScan:Generic.Dacic.A9349469.A.D2650359
FireEyeGeneric.mg.f650d24e0c240b98
ALYacDeepScan:Generic.Dacic.A9349469.A.D2650359
MalwarebytesRemcos.Backdoor.Bot.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057919d1 )
K7GWTrojan ( 0057919d1 )
Cybereasonmalicious.e0c240
ArcabitDeepScan:Generic.Dacic.A9349469.A.D2650359
CyrenW32/Trojan.GCT.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Rescoms.N
APEXMalicious
ClamAVWin.Trojan.Remcos-9841897-0
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderDeepScan:Generic.Dacic.A9349469.A.D2650359
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.11a2f1bc
SophosMal/Generic-S
F-SecureBackdoor.BDS/Backdoor.Gen
VIPREDeepScan:Generic.Dacic.A9349469.A.D2650359
McAfee-GW-EditionBehavesLike.Win32.NetLoader.gh
EmsisoftDeepScan:Generic.Dacic.A9349469.A.D2650359 (B)
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraBDS/Backdoor.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Rescoms
MicrosoftTrojan:Win32/Remcos!MTB
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataDeepScan:Generic.Dacic.A9349469.A.D2650359
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RemcosRAT.R580607
McAfeeGenericRXSQ-HG!F650D24E0C24
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
PandaTrj/GdSda.A
RisingBackdoor.Remcos!1.BAC7 (CLASSIC)
IkarusBackdoor.Remcos
FortinetW32/Remcos.M!tr
BitDefenderThetaGen:NN.ZexaF.36196.ACW@aeGML9ci
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Remcos.Backdoor.Bot.DDS?

Remcos.Backdoor.Bot.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment